« Volver al listado

CVE-2020-14159

Estado: ModificadaAlta (8.8)—

By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-14159",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-06-15T19:15:10.167",
  "references": [
    {
      "url": "https://www.connectwise.com/company/trust#tab1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.connectwise.com/company/trust#tab1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178."
    },
    {
      "lang": "es",
      "value": "Al usar una API de Automate en ConnectWise Automate versiones anteriores a 2020.5.178, un usuario autenticado remoto podría ejecutar comandos y/o modificaciones dentro de una instancia Automate individual activando una vulnerabilidad de inyección SQL en /LabTech/agent.aspx. Esto afecta a las versiones anteriores a 2019.12.337, 2020 anteriores a  2020.1.53, 2020.2 anteriores a 2020.2.85, 2020.3 anteriores a 2020.3.114, 2020.4 anteriores a  2020.4.143, y 2020.5 anteriores a 2020.5.178"
    }
  ],
  "lastModified": "2026-06-17T02:54:18.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C49706E-4112-45C0-93F2-E026D36BC16A",
              "versionEndExcluding": "2019.12.337"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A96D51FD-AF50-45E9-932E-D0D927B203C5",
              "versionEndExcluding": "2020.1.53",
              "versionStartIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E85F01D6-B8C9-4870-9B08-16EE7B835C27",
              "versionEndExcluding": "2020.2.85",
              "versionStartIncluding": "2020.2"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B5C743E-68AA-42D5-A839-3DC685479F0D",
              "versionEndExcluding": "2020.3.114",
              "versionStartIncluding": "2020.3"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A6C1FB7-F705-406E-B771-06E851C3EE97",
              "versionEndExcluding": "2020.4.143",
              "versionStartIncluding": "2020.4"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:automate_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C26CD1B0-18BA-40CA-841F-AD4727650CBD",
              "versionEndExcluding": "2020.5.178",
              "versionStartIncluding": "2020.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}